wolfSSL wolfProvider是wolfSSL公司的一个提供加密后端的provider库。 wolfSSL wolfProvider 1.2.2之前版本存在加密问题漏洞,该漏洞源于生成AES-GCM nonce时仅生成一次且未按记录递增,导致同一连接内TLS 1.2和DTLS 1.2记录重用相同密钥和nonce对,可能泄露密钥流和GHASH认证密钥,造成信息泄露和认证标签伪造。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wolfSSL Inc. | wolfProvider | ≤ 1.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wolfSSL Inc. | wolfProvider | 0 ~ 1.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81020 | 7.4 HIGH | wolfEngine reuses the AES-GCM nonce on every TLS 1.2 / DTLS 1.2 record |
| CVE-2026-81341 | 6.5 MEDIUM | wolfEngine reuses the AES-CCM nonce on TLS 1.2 / DTLS 1.2 records |
No comments yet